TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How secure are private Git repositories?

9 点作者 lma21大约 5 年前
Would you use them to version sensitive data?<p>Would Gitlab&#x2F;Github have access to the underlying content&#x2F;history?<p>I wouldn’t use them to store passwords or banking-related information, though how about medical&#x2F;income&#x2F;taxation documents or information?

2 条评论

rvz大约 5 年前
&gt; Would you use them to version sensitive data?<p>If you are using a self-hosted version of Github or preferably GitLab then yes. However, If you&#x27;re on GitHub or GitLab&#x27;s cloud version then it&#x27;s not secure and you have zero control, even if its private.<p>&gt; Would Gitlab&#x2F;Github have access to the underlying content&#x2F;history?<p>Who knows. But the first answer tells you that you will have more control in a self-hosted environment over a cloud based version and I wouldn&#x27;t risk putting sensitive data there unless I have complete control with a self-hosted open-source version (GitLab).<p>&gt; ...though how about medical&#x2F;income&#x2F;taxation documents or information?<p>Well that&#x27;s very sensitive data equivalent to bank-level information, which can be used as a reason for others to determine your job, insurance or loan choices. Thus, should be treated as sensitive too.
评论 #23058862 未加载
评论 #23059950 未加载
onebot大约 5 年前
I have often wondered this myself. Considering if github was ever compromised, could an attacker modify your source code without your knowledge. Seems like a holy grail of attacks.<p>What would be interesting if there was some at-rest encryption and maybe some audit functionality.
评论 #23058346 未加载